cbcvebase.
CVE-2025-23155
published 2025-05-01

CVE-2025-23155: In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Fix accessing freed irq affinity_hint In stmmac_request_irq_multi_msi(), a…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Fix accessing freed irq affinity_hint In stmmac_request_irq_multi_msi(), a pointer to the stack variable cpu_mask is passed to irq_set_affinity_hint(). This value is stored in irq_desc->affinity_hint, but once stmmac_request_irq_multi_msi() returns, the pointer becomes dangling. The affinity_hint is exposed via procfs with S_IRUGO permissions, allowing any unprivileged process to read it. Accessing this stale pointer can lead to: - a kernel oops or panic if the referenced memory has been released and unmapped, or - leakage of kernel data into userspace if the memory is re-used for other purposes. All platforms that use stmmac with PCI MSI (Intel, Loongson, etc) are affected.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 8deec94c6040bb4a767f6e9456a0a44c7f2e713e < 2fbf67ddb8a0d0efc00d2df496a9843ec318d48b2fbf67ddb8a0d0efc00d2df496a9843ec318d48b
linuxlinux>= 8deec94c6040bb4a767f6e9456a0a44c7f2e713e < 960dab23f6d405740c537d095f90a4ee9ddd9285960dab23f6d405740c537d095f90a4ee9ddd9285
linuxlinux>= 8deec94c6040bb4a767f6e9456a0a44c7f2e713e < 442312c2a90d60c7a5197246583fa91d9e579985442312c2a90d60c7a5197246583fa91d9e579985
linuxlinux>= 8deec94c6040bb4a767f6e9456a0a44c7f2e713e < e148266e104fce396ad624079a6812ac3a9982efe148266e104fce396ad624079a6812ac3a9982ef
linuxlinux>= 8deec94c6040bb4a767f6e9456a0a44c7f2e713e < 9e51a6a44e2c4de780a26e8fe110d708e806a8cd9e51a6a44e2c4de780a26e8fe110d708e806a8cd
linuxlinux>= 8deec94c6040bb4a767f6e9456a0a44c7f2e713e < c60d101a226f18e9a8f01bb4c6ca2b47dfcb15efc60d101a226f18e9a8f01bb4c6ca2b47dfcb15ef
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.13 < 6.12.366.12.36
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.